Show filters
386 Total Results
Displaying 191-200 of 386
Sort by:
Attacker Value
Unknown
CVE-2023-1774
Disclosure Date: March 31, 2023 (last updated February 24, 2025)
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
0
Attacker Value
Unknown
CVE-2023-1562
Disclosure Date: March 22, 2023 (last updated February 24, 2025)
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
0
Attacker Value
Unknown
CVE-2023-1421
Disclosure Date: March 15, 2023 (last updated February 24, 2025)
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
0
Attacker Value
Unknown
CVE-2023-27266
Disclosure Date: February 27, 2023 (last updated February 24, 2025)
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
0
Attacker Value
Unknown
CVE-2023-27265
Disclosure Date: February 27, 2023 (last updated February 24, 2025)
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
0
Attacker Value
Unknown
CVE-2023-27264
Disclosure Date: February 27, 2023 (last updated February 24, 2025)
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.
0
Attacker Value
Unknown
CVE-2023-27263
Disclosure Date: February 27, 2023 (last updated February 24, 2025)
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.
0
Attacker Value
Unknown
CVE-2022-4045
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data.
0
Attacker Value
Unknown
CVE-2022-4019
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.
0
Attacker Value
Unknown
CVE-2022-4044
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.
0